figma-swiftui
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external Figma designs and user-provided SwiftUI source files, creating a surface for indirect instructions to influence agent behavior.
- Ingestion points: Processes data from Figma file keys and node IDs through the
get_design_contexttool, as well as the contents of local.swiftfiles. - Boundary markers: The instructions provide explicit guidance to treat structural references (like React+Tailwind output) as metadata rather than literal source code, and emphasize using screenshots as the visual source of truth.
- Capability inventory: The skill has the ability to write SwiftUI code to the local filesystem and execute JavaScript scripts within the Figma environment using the
use_figmatool. - Sanitization: It implements strict semantic mapping rules (e.g., iOS HIG token mapping) and requires environment verification, such as checking for available fonts in Figma before performing operations.
- [DYNAMIC_EXECUTION]: The skill dynamically generates and executes JavaScript code to manipulate the Figma canvas based on the interpretation of SwiftUI source code.
- Evidence: The
references/code-to-design.mdfile contains detailed instructions for assemblinguse_figmascripts that call Figma API functions likefigma.createAutoLayout()andfigma.createText(). - Context: This dynamic execution is the primary mechanism for the skill's code-to-design functionality and uses provided utility helpers for asset and symbol handling.
Audit Metadata